Ecommerce Legal Requirements in Australia: Privacy, T&Cs and Consumer Law Explained

Running an online store in Australia is more regulated than most founders realise. Between the Privacy Act, the Australian Consumer Law, the Spam Act and a stack of obligations sitting underneath all three, the ecommerce legal requirements in Australia can feel like a maze, especially if you’re scaling fast on Shopify or WooCommerce and haven’t formalised the boring stuff yet.

The good news: most of it is manageable once you know what applies to you. The bad news: regulators have sharper teeth than they used to, and the cost of getting it wrong has gone up significantly over the last two years.

This guide breaks down the main legal obligations every Australian online business should understand, what’s changed recently, and where the common pain points sit.

Who enforces ecommerce legal requirements in Australia?

There isn’t a single “ecommerce law” in Australia. Online businesses sit at the intersection of several regulators, each enforcing different rules:

  • ACCC (Australian Competition and Consumer Commission): consumer law, advertising, misleading conduct, unfair contract terms.
  • OAIC (Office of the Australian Information Commissioner): privacy, personal information, data breaches.
  • ACMA (Australian Communications and Media Authority): email and SMS marketing under the Spam Act.
  • ATO and ASIC: tax, GST, business structure, director duties.
  • IP Australia: trademarks and intellectual property.

If you sell to Australian consumers, most of these will apply to you in some form, even if your business is registered overseas. The geography of your customers matters more than the geography of your servers.

Australian Consumer Law: what every online store needs to know

The Australian Consumer Law (ACL) sits inside the Competition and Consumer Act 2010. It applies to virtually every business selling goods or services to consumers in Australia, and it’s the rulebook the ACCC uses to take action against online stores that step out of line.

Consumer guarantees

Under the ACL, your products automatically come with guarantees that you can’t contract out of. They must be of acceptable quality, match their description, be fit for purpose, and arrive in a reasonable time. If they don’t, the customer is entitled to a repair, replacement or refund depending on whether the issue is major or minor. A “no refunds” sign on your checkout page doesn’t override this. Trying to enforce one can itself be a breach.

Misleading or deceptive conduct

Your product descriptions, marketing claims, before-and-after photos, scarcity timers and “limited time” pricing all need to be accurate. Inflating an RRP to make a sale price look bigger, faking reviews, or running fake countdown timers are all areas the ACCC has actively targeted online retailers over. The penalties for misleading conduct now run into the millions for corporations.

Unfair contract terms

Since November 2023, unfair contract terms in standard form contracts (including most online T&Cs) attract civil penalties, not just unenforceability. That’s a significant shift. If your terms unfairly lock customers into auto-renewals, allow you to change prices without notice, or strip them of statutory rights, you can now be fined. This applies to consumer contracts and many small business contracts as well.

Privacy obligations and the Privacy Act

If you collect customer email addresses, names, shipping addresses, payment details or browsing data (almost every ecommerce business does), you’re handling personal information. The Privacy Act 1988 and the Australian Privacy Principles (APPs) set out how you can collect, store, use and share that information.

Does the Privacy Act apply to your store?

Historically, businesses with annual turnover under $3 million were exempt from much of the Privacy Act under the “small business exemption”. That exemption is being narrowed and is likely to be removed entirely as the federal government works through its multi-tranche Privacy Act reforms. Even now, the exemption doesn’t apply if you trade in personal information, provide health services, or are a contracted service provider to a Commonwealth contract.

The safer working assumption for any growing ecommerce business: act as if the Act applies to you. The compliance cost is low compared to the risk of having to retrofit your privacy practices later.

What you need to have in place

  • A privacy policy that’s clear, accessible from your site, and accurately describes what information you collect, why, and who you share it with.
  • Consent mechanisms at the points where personal information is collected (signup forms, checkout, cookie banners).
  • Reasonable security measures to protect the personal information you hold.
  • A data breach response plan, so you can comply with the Notifiable Data Breaches scheme if something goes wrong.

Notifiable Data Breaches

If you experience a data breach that is likely to result in serious harm to the people whose information was leaked, you must notify both those people and the OAIC. The OAIC publishes detailed guidance for organisations on what counts as a notifiable breach and how to handle one. Penalties for serious or repeated breaches now reach into the tens of millions of dollars.

Website terms and conditions

Your website terms and conditions are the contract between your business and every customer who buys from you. They set out what you’ll deliver, how disputes will be handled, what intellectual property rules apply, and how you’ll limit liability where the law allows.

Well-drafted T&Cs typically cover:

  • Order acceptance and pricing errors
  • Payment, shipping and delivery terms
  • Returns, refunds and warranties (aligned with the ACL)
  • Intellectual property in your site, branding and product imagery
  • Limitation of liability (within what the ACL permits)
  • Governing law and dispute resolution

It’s tempting to copy a competitor’s T&Cs or grab a free template. The problem is that generic terms rarely match your actual business model, and the clauses that protect you most are often the ones that need customisation. We’ve covered this in more depth in our guide on website terms and conditions templates vs custom drafting for online stores.

The Spam Act: email and SMS marketing rules

If you send marketing emails or SMS to Australian customers, the Spam Act 2003 applies. Three core requirements:

  1. Consent: you need express or inferred consent before sending commercial electronic messages. A pre-ticked box at checkout is not valid consent.
  2. Identification: every message must clearly identify your business and provide accurate contact details.
  3. Unsubscribe: every commercial message must include a functional unsubscribe option that works for at least 30 days and is honoured within 5 business days.

ACMA actively fines businesses that breach these rules. Penalties have run from tens of thousands to millions of dollars for repeat or systemic breaches. ACMA publishes practical guidance on staying compliant that’s worth reviewing before any major campaign push.

Other obligations worth knowing about

GST and tax

If your turnover hits $75,000, you must register for GST. Imported low-value goods (under $1,000) sold to Australian consumers also attract GST in most cases, which is relevant if you dropship or sell internationally into Australia.

Intellectual property

Your brand name, logo and product designs are commercial assets. Registering trademarks early protects you from copycats and is significantly cheaper than fighting infringement after a competitor has built a market position off the back of your branding. The same applies to product photography, written content, and software you’ve developed in-house.

Supplier and platform agreements

Whether you’re sourcing stock from an overseas manufacturer, working with a dropshipping partner, or relying on a fulfilment provider, written agreements matter. Loose verbal arrangements fall apart fastest when stock doesn’t arrive, quality slips, or you decide to switch suppliers. A clear commercial agreement defines who’s responsible for what, what happens if things go wrong, and what your exit options look like.

Payment processing

You don’t directly need to comply with PCI-DSS if you’re using a hosted gateway like Stripe, Shopify Payments or PayPal, but you do need to understand what data flows through your systems and what your processor’s terms require of you. Storing card numbers in your CRM, for example, is a fast track to a compliance problem.

Common mistakes Australian ecommerce businesses make

  • Using a copied privacy policy that doesn’t reflect what the business actually collects or does with data.
  • Running “30% off” or RRP-based pricing claims without a defensible basis.
  • Trying to limit refunds in T&Cs in ways the ACL doesn’t permit.
  • Sending marketing emails to old customer lists without checking consent records.
  • Selling internationally without considering GST on low-value imports or overseas consumer protection laws.
  • Letting trademarks sit unregistered until a copycat forces the conversation.

Most of these are cheap to fix early and expensive to fix late.

Frequently asked questions

Do I need a privacy policy for my online store in Australia?

If the Privacy Act applies to your business, yes. Even if you’re currently under the small business exemption, most ecommerce platforms (Shopify, Klaviyo, Meta Ads) require you to have one as part of their terms. Practically speaking, every online store should have a privacy policy that accurately describes its data practices.

Are terms and conditions legally required for an Australian online store?

There’s no specific law that forces you to publish T&Cs, but without them you’re relying entirely on the default rules of contract and consumer law, with no ability to set your own pricing terms, shipping rules, or dispute process. For any business taking online payments, T&Cs are essentially non-negotiable.

Does the Australian Consumer Law apply to overseas customers?

The ACL primarily protects consumers in Australia. If you’re an Australian business selling to overseas customers, you may also need to comply with consumer laws in the destination country. If you’re an overseas business selling to Australians, the ACL can still apply to you. The ACCC has been actively pursuing offshore businesses that target Australian consumers.

What happens if my business breaches the Privacy Act?

Penalties depend on the severity. Minor breaches may result in undertakings or determinations from the OAIC. Serious or repeated breaches can attract civil penalties in the tens of millions of dollars for corporations, alongside reputational damage that often costs more than the fine itself.

Do I need an ABN to sell products online in Australia?

If you’re operating a business (rather than selling personal items casually), you generally need an ABN. You’ll also need to register for GST once your turnover reaches $75,000. Business.gov.au has a useful starting checklist for online businesses setting up in Australia.

Get tailored ecommerce legal advice

Most ecommerce founders don’t need a 50-page legal manual. They need someone who understands online business and can tell them, in plain English, what actually matters for their stage and model. That’s the gap we built our ecommerce legal services around. Whether you’re scaling a Shopify store, preparing for an acquisition, or just trying to get your T&Cs and privacy policy on solid ground, we can help you sort the compliance basics without slowing your business down.

Book a free 15-minute consultation with the New Wave Law team to talk through where your business sits and what’s worth tackling first.

This article is general information only and isn’t legal advice. Specific obligations depend on your business, your customers and the way you collect and use data. Get tailored advice before relying on any of the above.

Related Articles

Trusted Lawyers on the Gold Coast for Commercial & Business Legal Services

Get in touch for a FREE consultation.

Get in touch for a free chat,
or we can come to you!